Azure Security Engineer
Role details
Job location
Tech stack
Job description
The Azure Security Engineer will support a large team of infrastructure, security and application team during migration of on-prem and cloud applications to the client Azure Government enclave. The Azure security engineer will configure, operate and maintain Azure cloud native tools. The engineer will provide support for security assessment and authorization/ATO process, security audits and will operate and maintain Azure security tools for security monitoring, analysis, and reporting.
Requirements
-
5+ years' experience configuring, deploying and maintaining and optimizing Azrue Security cloud native tools:
-
Azure Sentinel including User and Entity Behavior Analytics (UEBA), and Security Orchestration, Automation and Response (SOAR)
-
Azure Defender including Endpoint Detection and Response (EDR) and Cloud Security Posture Management (CSPM) and Azure Cloud Workload Protection (CWPP).
-
Azure Purview (Data Loss Prevention)
-
Azure Defender for Cloud
-
Azure Log Analytics
-
Experienced with KQL;
-
Configure rules for real-time alerting in SIEM tool for events;
-
Provide security monitoring including log aggregation/centralization, correlation, and alerting of security events and incidents;
-
Review and analyze audit records weekly for identified unusual activity and provide evidence of review and/or findings;
-
Support incident response activities;
-
Microsoft Azure Security related certifications are strongly recommended;
-
Experience implementing security controls and policies, managing access to data, and monitoring threats to ensure that data, applications, infrastructure, and networks are protected;
-
Experience with Security Assessment and Authorization (ATO) process;
-
Support audit data calls;
-
Bachelor's Degree;
-
U.S. Citizen;
-
Ability to acquire a Public Trust Background investigation.
Preferred technical and professional experience
-
SC-200: Microsoft Security Operations Analyst/ SC-100 Cybersecurity Architect Expert/AZ/SC-500 Azure Security Engineer Associate
-
Experience with Windows and Linux Administration
-
Certified in industry recognized areas such as CISSP, CISA, or CISM